Privacy
Effective October 1, 2026
Mantis is built to need as little data as possible. This policy describes what the current version of the Mantis iPhone app and mantis.hurstsystems.com collect. You can read stories as a guest without an account. The app contains no advertising or tracking code, and its usage analytics go only to our own server.
Reading stories
Reading stories needs no personal information. The app downloads stories from our server, which, like most web servers, records each request's IP address, time, address requested, and app or browser version. We use these logs only to keep the service secure and working, and delete them after 14 days.
Your account
Alerts, following stories, choosing topics and reporting problems need a free account. You can sign in with Apple, with Google, or with an email and password. Our server stores:
- a random account ID, and the name and email you or your sign-in provider share with us (Sign in with Apple lets you hide your email behind an Apple relay address);
- for Apple and Google, the provider's ID for your account, so it can recognize you next time. We never see or store your Apple or Google password;
- for email sign-in, your email and a salted, one-way scrypt hash of your password. Your password itself is never stored or logged. To confirm your address or reset your password we email you a six-digit code through our email provider; we store only a one-way hash of it, and it expires after 15 minutes;
- the topics you follow, any alert filters you write, and whether you finished setting up;
- problems you report with a story: which story and version, the reason you pick, any note you write, and when;
- for each signed-in device, a one-way hash of a random session token (the token itself stays in your iPhone's Keychain), and when it was created and last used.
We use this only to sign you in, to send you alerts for the topics you follow, and to fix stories you report; reports reach the Mantis team by email without your name or email. We do not sell it or share it with anyone else, except alert filters as described next.
Alert filters are optional instructions, in your own words, for which alerts you want. To check an alert against them, we send your filters and the alert's text, and nothing that identifies you, to TypeSafe, the AI service behind Mantis AI. We send them only for that check, and to show you how your filters would have handled your recent alerts.
Alerts
If you turn alerts on, the app registers your iPhone with our server, which stores:
- a random installation ID created by the app;
- a one-way hash of a random secret that proves requests come from your installation (the ID and secret stay in your iPhone's Keychain);
- the push token Apple issues for Mantis on your iPhone, and whether it is for Apple's development or production push service;
- whether alerts are on, and when the registration was created and last changed;
- for each alert, which story it was for, whether it was delivered, and when.
We use this only to send you Mantis alerts. Alerts are delivered through the Apple Push Notification service, so Apple receives your push token and the alert's text. While you are signed in, your installation is linked to your account so alerts follow your topics; signing out removes the link. We do not sell this data or share it with anyone else.
Usage analytics
To learn which parts of Mantis are useful, the app records what you do in it, such as screens you view, stories and sources you open, alerts you tap, and whether setup and sign-in succeeded, with your app and iOS versions. Each event is stored on our server under a random ID the app creates for itself, not your device's identifiers, and is linked to your account while you are signed in. Events never include your name, email, search text or alert filter wording. We use them only to improve Mantis; they are not sent to any analytics or advertising company, and are not used to track you across other apps or websites.
Deleting your data
- Deleting your account in Mantis (Settings, then Delete Account) erases your account, sign-in details, topics, alert filters, sessions, and the usage events linked to your account from our server immediately, and the app starts a new random analytics ID. Problems you reported with stories are kept, no longer linked to you.
- Signing out ends that device's session on our server.
- If you signed in with Apple, deleting your account also tells Apple to end Mantis's access to your Apple ID.
- Turning alerts off in Mantis deletes your installation, push token, and alert history from our server immediately.
- If Apple tells us your push token is no longer valid (for example, after you delete the app), we delete the token.
- Database backups, kept for 14 days, can hold a copy until they expire.
Where stories come from
Stories are written from public Polymarket market data and public news reporting, using OpenAI's models. None of your data is sent to Polymarket, OpenAI, or any other service to write them.
Children
Mantis is not directed at children under 13, and we do not knowingly collect data from them.
Changes
Mantis will change as it grows and may add features such as subscriptions. Before a change to what data Mantis collects or how it is used takes effect, we will post the updated policy here with a new effective date, and tell you in the app when the change is significant.
Contact
Questions or requests: josh@hurstsystems.com.